Hacker News new | ask | show | jobs
by inglor 78 days ago
We mitigate this attack with the very uninspiring "wait 24h before dep upgrades" solution which is luckily already supported in uv.
1 comments

Yeah, but uvx has this thing where it can automatically build the latest environment, and pull the latest (unpinned) version, right?